forked from elastic/kibana
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge branch 'master' of github.com:elastic/kibana into reporting/new…
…-png-pdf-report-type * 'master' of github.com:elastic/kibana: (447 commits) skip flaky suite (elastic#102366) [Security Solution][Endpoint][Host Isolation] Isolation status badge from alert details (elastic#102274) Add email connector info for Elastic Cloud (elastic#91363) [Workplace Search] remove or replace xs props for text on source connect view (elastic#102663) Do not double register dashboard url generator (elastic#102599) [TSVB] Replaces EuiCodeEditor 👉 Monaco editor (elastic#100684) [Discover] Update kibana.json adding owner and description (elastic#102292) [Exploratory View] Mobile experience (elastic#99565) chore(NA): moving @kbn/ui-shared-deps into bazel (elastic#101669) [TSVB] Index pattern select field disappear in Annotation tab (elastic#102314) [Security Solution][Endpoint][Host Isolation] Fixes bug where host isolation/unisolation works from alert details (elastic#102581) TSVB visualizations with no timefield do not render after upgrading from 7.12.1 to 7.13.0 (elastic#102494) [Logs UI] Add `event.original` fallback to message reconstruction rules (elastic#102236) [ML] Remove blank job definition as it is unused and out-of-sync with Elasticsearch (elastic#102506) [Lens] Fix wrong error detection on transition to Top values operation (elastic#102384) [ML] Anomaly detection job custom_settings improvements (elastic#102099) [Cases] Route: Get all alerts attach to a case (elastic#101878) Fixes wrong list exception type when creating endpoint event filters list (elastic#102522) remove search bar that's not working yet (elastic#102550) Migrated Ingest Node Pipeline Functional Tests to use test_user (elastic#102409) ... # Conflicts: # x-pack/plugins/reporting/public/share_context_menu/register_pdf_png_reporting.tsx
- Loading branch information
Showing
6,349 changed files
with
202,816 additions
and
113,875 deletions.
The diff you're trying to view is too large. We only load the first 3000 changed files.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,63 @@ | ||
# Risk consideration | ||
|
||
When merging a new feature of considerable size or modifying an existing one, | ||
consider adding a *Risk Matrix* section to your PR in collaboration with other | ||
developers on your team and the QA team. | ||
|
||
Below are some general themes to consider for the *Risk Matrix*. (Feel free to | ||
add to this list.) | ||
|
||
|
||
## General risks | ||
|
||
- What happens when your feature is used in a non-default space or a custom | ||
space? | ||
- What happens when there are multiple Kibana nodes using the same Elasticsearch | ||
cluster? | ||
- What happens when a plugin you depend on is disabled? | ||
- What happens when a feature you depend on is disabled? | ||
- Is your change working correctly regardless of `kibana.yml` configuration or | ||
UI Setting configuration? (For example, does it support both | ||
`state:storeInSessionStorage` UI setting states?) | ||
- What happens when a third party integration you depend on is not responding? | ||
- How is authentication handled with third party services? | ||
- Does the feature work in Elastic Cloud? | ||
- Does the feature create a setting that needs to be exposed, or configured | ||
differently than the default, on the Elastic Cloud? | ||
- Is there a significant performance impact that may affect Cloud Kibana | ||
instances? | ||
- Does your feature need to be aware of running in a container? | ||
- Does the feature Work with security disabled, or fails gracefully? | ||
- Are there performance risks associated with your feature? Does it potentially | ||
access or create: (1) many fields; (2) many indices; (3) lots of data; | ||
(4) lots of saved objects; (5) large saved objects. | ||
- Could this cause memory to leak in either the browser or server? | ||
- Will your feature still work if Kibana is run behind a reverse proxy? | ||
- Does your feature affect other plugins? | ||
- If you write to the file system, what happens if Kibana node goes down? What | ||
happens if there are multiple Kibana nodes? | ||
- Are migrations handled gracefully? Does the feature affect old indices or | ||
saved objects? | ||
- Are you using any technologies, protocols, techniques, conventions, libraries, | ||
NPM modules, etc. that may be new or unprecedented in Kibana? | ||
|
||
|
||
## Security risks | ||
|
||
Check to ensure that best practices are used to mitigate common vulnerabilities: | ||
|
||
- Cross-site scripting (XSS) | ||
- Cross-site request forgery (CSRF) | ||
- Remote-code execution (RCE) | ||
- Server-side request forgery (SSRF) | ||
- Prototype pollution | ||
- Information disclosure | ||
- Tabnabbing | ||
|
||
In addition to these risks, in general, server-side input validation should be | ||
implemented as strictly as possible. Extra care should be taken when user input | ||
is used to construct URLs or data structures; this is a common source of | ||
injection attacks and other vulnerabilities. For more information on all of | ||
these topics, see [Security best practices][security-best-practices]. | ||
|
||
[security-best-practices]: https://www.elastic.co/guide/en/kibana/master/security-best-practices.html |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.